ralph-tdd
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the skill’s core purpose is coherent, but it intentionally grants an AI agent broad AFK autonomy to read backlog content, execute shell commands, modify code, update trackers, and commit changes. The biggest risks are autonomous real-world actions, transitive skill installation, and prompt-injection exposure from external task sources rather than overt malware or credential theft.
Confidence: 90%Severity: 81%
Audit Metadata